CVE-2025-22849 Details
Description
Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584, CR_MGMT_02.00.00.4052, CR_MGMT_03.00.00.0538 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
A privilege escalation vulnerability has been identified in the Intel Optane PMem management software, affecting versions prior to CR_MGMT_01.00.00.3584, CR_MGMT_02.00.00.4052, and CR_MGMT_03.00.00.0538. The vulnerability arises from incorrect default permissions, which may allow an unprivileged, authenticated user to escalate privileges. Exploitation of this vulnerability could occur through local access, requiring active user interaction and without special internal knowledge. The vulnerability has the potential to impact the system's confidentiality, integrity, and availability, although these impacts would not extend to the system's overall confidentiality, integrity, or availability.
Users are advised to update the Intel Optane PMem management software to versions CR_MGMT_01.00.00.3584, CR_MGMT_02.00.00.4052, or CR_MGMT_03.00.00.0538. Version CR_MGMT_02.00.00.4052 is only applicable for Windows operating systems. After June 30, 2025, Intel Optane PMem 100 Series management software will no longer be supported, and users are recommended to migrate to a newer generation product.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 10, 2026CISA-ADP
Assessed Feb 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01323.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Intel Optane PMem Management Software | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 10, 2026 | New CVE Received | [email protected] |
Volerion